Skip to content

Feature: Implement Refresh Rotation and Logout API #79

Description

@3m1n3nc3

Description

Replace stateless logout with rotating refresh sessions, reuse detection, and revocation.

File Location

Session service, auth routes/controllers/middleware, and tests

Design Reference

API Roadmap Phase 1: Implement Refresh Rotation and Logout API.

Dependencies

  • Status: Blocked
  • Blocked by: Feature: Add Auth Token and Session Persistence Models; Feature: Standardize API Contracts Pagination and Versioning
  • Blocks: Feature: Expose Session and Device Management API; Feature: Harden Authentication and Account Security Policy

Tasks

  • Issue short-lived access and opaque refresh tokens at login
  • Rotate refresh token atomically with family linkage
  • Detect rotated-token reuse and revoke the family
  • Add logout current and logout all sessions
  • Document cookie/header transport and CSRF policy
  • Test races, replay, expiry, revocation, and logout

Acceptance Criteria

  • Refresh rotates once per valid use
  • Replay triggers documented family revocation
  • Logout prevents targeted refresh
  • Transport is documented and tested
  • OpenAPI passes

Verification Evidence

  • Attach redacted login/refresh/logout curl and replay tests

Difficulty

Advanced

Metadata

Metadata

Assignees

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions